# Packetbeat cannot parse Tomcat's response status line because of reason phrase

**URL:** <https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 16, 2018, 7:10am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223 "2018-03-16T07:10:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cero-t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cero-t/32/28149_2.png) [@cero-t](https://discuss.elastic.co/u/cero-t)\
**Post date:** [March 16, 2018, 7:10am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/1 "2018-03-16T07:10:37Z")

</div>

I tried to use Packetbeat 6.2.2 to capture packets of Tomcat request / response but failed to capture with this error.

```auto
http/http_parser.go(156) Failed to understand HTTP response status: 200

```

Tomcat (\> 8.5) returns only the response status code without reason phrase by default, but packetbeat's parser expects the reason phrase and it cause above error. I think the spec of HTTP 1.1 (RFC 2616) is ambiguous regarding whether the reason phrase is optional or required. I think a "space" is required, but the "phrase" is not required.

> <https://github.com/elastic/beats/blob/master/packetbeat/protos/http/http_parser.go#L210>

RFC 2616  
[https://tools.ietf.org/html/rfc2616#section-6.1](https://tools.ietf.org/html/rfc2616#section-6.1)

Then, is it reasonable to modify Packetbeat to be enabled to parse the response status line without any reason phrase?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 16, 2018, 8:56am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/2 "2018-03-16T08:56:22Z")

</div>

Hmmm.... this sounds somewhat familiar to me. If servers do give this kind of response-code-only-response, packetbeat should support this. Do you plan to create a pull request? Otherwise, just [open an issue](https://github.com/elastic/beats/issues).

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [March 16, 2018, 9:31am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/3 "2018-03-16T09:31:10Z")

</div>

A fix for this was already merged ([#6208](https://github.com/elastic/beats/pull/6208)) but we have failed to backport it to 6.2.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [March 16, 2018, 10:14am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/4 "2018-03-16T10:14:49Z")

</div>

The fix won't make it to 6.2.3, but it will be available in the next version, most likely 6.3.0

---

<div class="post-metadata">

**Author:** ![cero-t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cero-t/32/28149_2.png) [@cero-t](https://discuss.elastic.co/u/cero-t)\
**Post date:** [March 17, 2018, 9:14am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/5 "2018-03-17T09:14:34Z")

</div>

Thanks, I'm grad to here that. I'll wait for 6.3!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2018, 9:14am UTC](https://discuss.elastic.co/t/packetbeat-cannot-parse-tomcats-response-status-line-because-of-reason-phrase/124223/6 "2018-04-14T09:14:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
